Overview

Play ransomware launched in June 2022, since which time organisations across the world have been successfully targeted. The ransomware has notoriously targeted organisations in the Latin American region, mainly Brazil. The Play ransomware group has previously been observed to have used various infection vectors within their attack chain. Examples include the use of Cobalt Strike for post-compromise operations and SystemBC RAT with regards to target persistence. Play ransomware consistently targets compromised valid accounts or unpatched Fortinet SSL VPN vulnerabilities as a means of establishing a foothold in the target network. As with the majority of modern ransomware1 variants, Play uses living-off-the-land binaries (LOLBins) to achieve its objective within target systems. These include the use of WinSCP for data exfiltration purposes as well as the Task Manager for Local Security Authority Server Service (LSASS) process dumping.

More recent Play ransomware campaigns have involved the exploitation of the ‘ProxyNotShell’ vulnerabilities discovered in Microsoft Exchange. Play ransomware is also known to employ similar behavioural trends and tactics as the HIVE and Nokoyawa ransomware variants2.

Play ransomware has been deployed in prominent attack campaigns, including those against Argentina’s Judiciary of Cordoba in August 2022 and more recently against network systems in the City of Oakland in March 2023.

In April 2023, the Play ransomware group were detected to have implemented campaigns involving the development of two custom tools in .NET, namely “Grixba” and “VSS Copying Tool”.

The Quorum Cyber Threat Intelligence team provides ransomware reports so that you can better understand the threats facing your organisation.

Download this report

Further Malware Reports from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

Colorado, USA Office

950 S Cherry St Ste 505
Denver, Colorado
USA
80246

Colorado, USA Office

950 S Cherry St Ste 505
Denver, Colorado
USA
80246

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Arizona, USA Office

1300 S Litchfield Rd
110-L, Goodyear
USA
Arizona 85338

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

950 S Cherry St Ste 505
Denver, Colorado
USA
80246

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



COLORADO, USA OFFICE
950 S Cherry St Ste 505
Denver, Colorado
USA
80246


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content